AI is showing up in more corners of plan administration: personalized communications, claims processing, investment reviews, even committee minutes. The time savings are real. But so are the risks, and ERISA fiduciaries don’t get to outsource accountability just because they’ve outsourced the work.
Carol Buckmann of Cohen & Buckmann, a New York-based executive compensation and benefits law firm, walked through the risks and implications in a recent post. Even if a plan sponsor isn’t using AI internally, she wrote, their recordkeeper and other third-party providers almost certainly are. Which means plan sponsors need to understand how AI is being used on their behalf, even if they don’t choose to adopt it themselves.
Ms. Buckmann cited several areas where AI use can create exposure:
Communications and disclosures. Personalized messages sound great until one of them leaves out something the IRS, DOL, or PBGC requires. A deficient Form 5500 can trigger penalties. A disclosure that omits material information can give participants grounds to claim additional benefits. Human review isn’t optional.
Claims and appeals. AI is among the most prevalent here, as many TPAs use it to process health plan claims. Even if the TPA is a named fiduciary, incorrect decisions or biased algorithms still affect employees whose coverage gets denied. And if the responsible fiduciaries didn’t vet the TPA’s procedures or algorithms, they could be on the hook for imprudent hiring. HIPAA adds another layer: fiduciaries should be asking whether AI introduces new risks around protected health information.
Investment selection and review. Programs now review a plan’s investment menu and compare performance against benchmarks. Useful? Sure. But Ms. Buckmann cautioned that fiduciaries should think carefully about whether these tools should replace—or just supplement—a 3(21) investment adviser or 3(38) manager. Live fiduciaries know the plan and its participants. They can attend meetings and answer questions. AI programs can crunch data quickly, but fiduciaries should still be asking about time frames, benchmark appropriateness, and potential conflicts of interest.
Committee minutes. According to Ms. Buckmann, most of the AI-generated minutes she sees are deficient. They either read like verbatim transcripts—full of comments plaintiffs’ lawyers can easily take out of context—or they’re so short that they leave out legally significant points. Either way, litigation risk increases. If AI is creating a first draft, someone who attended the meeting needs to review it carefully, not just for style, but for substance.
Confidentiality. Features like “summarize for me” can inadvertently expose non-public personal information. Agentic AI has direct access to files, which raises the stakes. The result could be HIPAA violations or other breaches of participant data.
Service agreements. Just as fiduciaries have started adding cybersecurity provisions to vendor contracts, Ms. Buckmann noted they should negotiate AI-specific terms: how the vendor uses AI, what review process catches errors, how data security is maintained, and whether the plan sponsor can review participant communications and filings before they go out.
Fiduciaries don’t need to avoid AI. But they shouldn’t confuse faster output with less responsibility. The tools are new. The fiduciary standard isn’t.